AI laws and regulations are evolving faster than most organizations can update their compliance processes. Setting up a new process for every single new rule is a losing battle.
The EU AI Act is gradually coming into effect, sector-specific regulations are following suit, and regulators are further refining their expectations with each new generation of AI models. This acceleration is not temporary. As long as AI models themselves continue to evolve rapidly, the regulations surrounding them will evolve as well.
For platform builders in regulated sectors (legal, finance, insurance, and accounting), this means, for example, that compliance must be a central focus of your product development. With the right frameworks in place, it’s easier to stay in control in a rapidly changing landscape. But how can your information and security department ensure that your organization maintains control over this?
Establishing Compliance as a Framework
In our industry, we don’t make a distinction often enough: compliance as the “police of ‘no’” versus compliance as a framework that actually provides flexibility amid rapid change. A team that knows exactly what is and isn’t allowed moves faster than a team that has to check whether something is permitted with every decision.
That does place some demands on the organization: clear guidelines upfront, rather than ad hoc approvals afterward. At Blinqx, I also incorporate that principle into our own platform architecture, so that teams can work independently within a defined scope without having to request a compliance check for every step.
How do you build your own control framework that easily accommodates new AI legislation?
The core of my approach is simple to articulate;
First, look at what you already have, not at everything you have to do
Identify the controls your organization already has in place before looking at external regulations. Only then should you compare those controls with the new GDPR, DORA, the AI Act, and other regulations to determine where coverage already exists and where additional measures are needed. This will help you avoid unnecessary or duplicate controls.
Integrate the new rules with your existing framework
Without your own framework, you end up creating a separate process for every new law, even though four or five of those processes essentially cover the same ground in practice. With your own framework, you can translate a new regulation into an update to an existing control, rather than a completely new process.
Report on risks and trends rather than vulnerabilities or compliance checklists
In regulated sectors, where multiple regulators impose requirements simultaneously, this work can sometimes be daunting for executives. My point is precisely that by first defining for yourself—as a CISO—what you consider important, you can maintain control over an ever-growing pile of external requirements rather than being overwhelmed by them. Report on this in a way that allows a board member without a technical background to grasp the essence.
Stay in control while factoring in risks.
I’d also like to mention a prerequisite that platform builders often overlook: identify which suppliers or technologies could disrupt your services, and determine in advance how long you could operate without any of them. This touches on the same issue as AI compliance: keeping your vulnerabilities under control before an external party exposes them for you.
Why This Works in the AI Era
The most important lesson is that you can’t keep up with AI regulations by remaining reactive. Platform builders who repeatedly wait until a new law is finalized before building a process are structurally playing catch-up. Those who establish their own control framework first only need to determine how it aligns with a new law when it’s enacted.
Want to dive deeper into this? I discussed this on Tech TalQX, Blinqx’s podcast where we regularly talk with colleagues about AI in regulated sectors.
Frequently Asked Questions
Because AI models themselves are changing faster than ever before, and the regulations surrounding them are evolving at the same pace. The AI Act, sector-specific regulations, and supervisory requirements are coming into effect more rapidly than organizations can update their internal processes, making a reactive approach no longer feasible.
A custom control framework is a set of controls that you define yourself based on what your organization considers important, independent of external regulations. You then link each external law to an existing control, rather than creating a new checklist for each law. This prevents you from setting up multiple processes that, in practice, cover the same ground.
By reporting on risks and trends rather than on technical details or the number of vulnerabilities. A manager does not need to know how a control works from a technical standpoint, but they do need to know what risk it poses to the organization and whether that risk is increasing or decreasing.
The risk is that your organization will come to a standstill as soon as the next law is enacted. AI compliance is an ongoing process, not a one-time effort that you complete and then set aside. Anyone who views it as a project will fall behind as soon as the next legislative change takes effect.
A bigger role than most platform builders realize. If a technology or vendor on which your services rely becomes unavailable or falls under foreign regulations, you want to know in advance how long you can operate without it and what your alternatives are. That’s just as much a part of compliance as adhering to the AI Act itself.